← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Google suspends open-source bug bounty program due to invalid AI-generated submissions

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Google suspended OSS VRP product vulnerability submissions on October 1.
  • The suspension is due to an influx of invalid AI-generated bug reports.
  • Engineers were overwhelmed validating false reports instead of fixing real vulnerabilities.
  • Google plans to provide an update by Q1 2027 after reformatting the program.

Google Suspends OSS VRP Submissions

Google has officially suspended product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The suspension went into effect on October 1, 2024, the day of the announcement. This decision does not affect product vulnerabilities submitted before this date, nor does it impact OSS VRP supply chain reports. Google indicated it might still accept reports for some Google Cloud repositories through the Cloud VRP.

Impact of AI-Generated Reports

The primary reason for the suspension is an influx of invalid bug reports driven by AI. The rise of large language models (LLMs) and automated AI bug-hunting scripts has significantly reduced the cost and effort required to generate bug reports, leading to a surge of low-effort, AI-generated submissions. These reports often claim to find bugs but are invalid or unexploitable hallucinations.

Overwhelmed Engineers and Maintainers

Google engineers and open-source maintainers were reportedly overwhelmed by thousands of these poorly written reports. They spent excessive time manually validating code that contained no actual vulnerabilities, diverting resources from fixing legitimate, critical security flaws. This inefficiency directly led to the program's suspension.

Industry-Wide Challenge

Similar issues have been observed across the tech industry. Linux maintainers reported being overwhelmed by CVE finds after AI-powered bug hunters increased the Linux kernel's vulnerability count to 2,000 per release. Intel also suspended its bug bounty program, with experts suspecting AI-generated reports as the cause, though the company did not officially confirm it. Google has committed to providing an update on its OSS VRP by the first quarter of 2027, indicating a period of reformatting and work on the program.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 20 stories · Oct 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Google has suspended its Open Source Software Vulnerability Reward Program (OSS VRP) for product vulnerabilities, effective October 1, 2024. This action was taken due to an overwhelming number of invalid bug reports generated by AI, which burdened engineers and maintainers. The suspension highlights a growing challenge in cybersecurity as AI-driven tools generate false positives, impacting resource allocation for legitimate security work.